Show filters
130 Total Results
Displaying 111-120 of 130
Sort by:
Attacker Value
Unknown
CVE-2008-2330
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
0
Attacker Value
Unknown
CVE-2008-2331
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
0
Attacker Value
Unknown
CVE-2008-3613
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving a search for a remote disk on the local network.
0
Attacker Value
Unknown
CVE-2008-3616
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
0
Attacker Value
Unknown
CVE-2008-3609
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.
0
Attacker Value
Unknown
CVE-2008-2305
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
0
Attacker Value
Unknown
CVE-2008-2332
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
0
Attacker Value
Unknown
CVE-2008-3618
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.
0
Attacker Value
Unknown
CVE-2008-3610
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
0
Attacker Value
Unknown
CVE-2008-3608
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
0